CVE-2014-8143
published 2015-01-17CVE-2014-8143: Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote…
PriorityP345high8.5CVSS 2.0
AVNACMAuSCCICAC
EPSS
4.26%
90.0th percentile
Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently gain privileges, by leveraging delegation of authority for user-account or computer-account creation.
Affected
46 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | samba | < samba 2:4.1.17+dfsg-1 (bookworm) | samba 2:4.1.17+dfsg-1 (bookworm) |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
| samba | samba | — | — |
CVSS provenance
nvdv2.08.5HIGHAV:N/AC:M/Au:S/C:C/I:C/A:C
osv8.5HIGH
vendor_debian8.5HIGH
vendor_redhat8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Samba vulnerability
vendor_ubuntu·2015-01-22
CVE-2014-8143 Samba vulnerability
Title: Samba vulnerability
Summary: A security issue was fixed in Samba.
Andrew Bartlett discovered that Samba incorrectly handled delegation of
authority when being used as an Active Directory Domain Controller. An
attacker given delegation privileges could use this issue to escalate their
privileges further.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
samba: Privileges elevation to Active Directory Domain Controller
vendor_redhat·2015-01-15·CVSS 8.5
CVE-2014-8143 [HIGH] CWE-345 samba: Privileges elevation to Active Directory Domain Controller
samba: Privileges elevation to Active Directory Domain Controller
Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently gain privileges, by leveraging delegation of authority for user-account or computer-account creation.
Statement: Not vulnerable. This issue did not affect the versions of samba as shipped with Red Hat Enterprise Linux 5, 6 and 7, and Red Hat Storage 2.1 and 3.0, versions of samba3x as shipped with Red Hat Enterprise Linux 5, versions of samba4 as shipped with Red Hat Enterprise Linux 6, as they did not include support for Samba Active Directory Domain Controller. All shipped
Debian
CVE-2014-8143: samba - Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an...
vendor_debian·2014·CVSS 8.5
CVE-2014-8143 [HIGH] CVE-2014-8143: samba - Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an...
Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently gain privileges, by leveraging delegation of authority for user-account or computer-account creation.
Scope: local
bookworm: resolved (fixed in 2:4.1.17+dfsg-1)
bullseye: resolved (fixed in 2:4.1.17+dfsg-1)
forky: resolved (fixed in 2:4.1.17+dfsg-1)
sid: resolved (fixed in 2:4.1.17+dfsg-1)
trixie: resolved (fixed in 2:4.1.17+dfsg-1)
GHSA
GHSA-g37q-w784-mfjr: Samba 4
ghsa_unreviewed·2022-05-17
CVE-2014-8143 [HIGH] GHSA-g37q-w784-mfjr: Samba 4
Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently gain privileges, by leveraging delegation of authority for user-account or computer-account creation.
OSV
CVE-2014-8143: Samba 4
osv·2015-01-17·CVSS 8.5
CVE-2014-8143 [HIGH] CVE-2014-8143: Samba 4
Samba 4.0.x before 4.0.24, 4.1.x before 4.1.16, and 4.2.x before 4.2rc4, when an Active Directory Domain Controller (AD DC) is configured, allows remote authenticated users to set the LDB userAccountControl UF_SERVER_TRUST_ACCOUNT bit, and consequently gain privileges, by leveraging delegation of authority for user-account or computer-account creation.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.htmlhttp://secunia.com/advisories/62594http://www.securityfocus.com/bid/72278http://www.securitytracker.com/id/1031615http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.416326http://www.ubuntu.com/usn/USN-2481-1https://download.samba.org/pub/samba/patches/security/samba-4.0.23-CVE-2014-8143.patchhttps://download.samba.org/pub/samba/patches/security/samba-4.1.15-CVE-2014-8143.patchhttps://exchange.xforce.ibmcloud.com/vulnerabilities/100596https://www.samba.org/samba/security/CVE-2014-8143http://lists.opensuse.org/opensuse-security-announce/2015-02/msg00031.htmlhttp://lists.opensuse.org/opensuse-security-announce/2016-04/msg00042.htmlhttp://secunia.com/advisories/62594http://www.securityfocus.com/bid/72278http://www.securitytracker.com/id/1031615http://www.slackware.com/security/viewer.php?l=slackware-security&y=2015&m=slackware-security.416326http://www.ubuntu.com/usn/USN-2481-1https://download.samba.org/pub/samba/patches/security/samba-4.0.23-CVE-2014-8143.patchhttps://download.samba.org/pub/samba/patches/security/samba-4.1.15-CVE-2014-8143.patchhttps://exchange.xforce.ibmcloud.com/vulnerabilities/100596https://www.samba.org/samba/security/CVE-2014-8143
2015-01-17
Published